Compliance

FCA Compliance Consultant: Scope, Costs and How to Choose

Regulatory Counsel · Published August 2026 · Last reviewed August 2026 · 10 min read

Key Takeaways

  • A compliance consultant supplements the firm's own arrangements. Accountability under SYSC and SM&CR remains with the firm and its senior managers at all times.
  • The three common engagement models are project-based authorisation support, retained ongoing compliance support, and independent review or audit work.
  • Fee models vary between fixed-fee project scopes, monthly retainers priced against a defined hour allocation, and day rates for specialist review work.
  • The FCA expects outsourced compliance arrangements to meet SYSC 8 requirements, including written agreements, oversight and exit planning.
  • Selection should turn on sector-specific authorisation experience, regulator engagement track record, and who actually performs the work.
Compliance consultant reviewing regulatory documentation with a client across a boardroom table in a London office

Most FCA-regulated firms use external compliance support at some point. Smaller payment institutions, e-money institutions, cryptoasset firms, consumer credit lenders and investment firms rarely carry the full range of specialist capability in-house, and larger firms use external support for peak workloads, independent review and regulator-facing projects.

The difficulty is that "compliance consultant" describes a very wide range of work, delivered at very different levels of quality. This article sets out what the role covers, how engagements are typically structured and priced, what the FCA expects where compliance activity is outsourced, and the questions to ask before appointing anyone.

What an FCA compliance consultant does

The work divides into four broad categories.

Authorisation and permissions. Preparing FCA applications, including the regulatory business plan, financial projections, governance maps, policy suite and Connect submission, then managing case officer correspondence through to determination. This also covers variations of permission, change in control notifications and cancellations. See our step by step guide to the FCA authorisation process.

Ongoing compliance support. Acting as an external resource to the compliance function: maintaining the policy suite, running the compliance monitoring programme, preparing board and committee reporting, tracking regulatory change, supporting regulatory returns and advising on live business questions as they arise.

Independent review and assurance. Compliance audits, financial crime framework reviews, safeguarding and client asset reviews, permissions reviews, Consumer Duty assessments, and readiness work ahead of an FCA visit or a skilled person review under section 166.

Remediation and regulator engagement. Responding to Dear CEO letters, supervisory information requests, voluntary requirements, past business reviews and enforcement-adjacent workstreams.

When firms appoint one

There are recognisable trigger points.

Applying for authorisation. First-time applicants routinely underestimate the evidential standard. Incomplete applications are the main cause of extended assessment periods.

Growth beyond the existing framework. New products, new customer segments, new jurisdictions or agent networks create obligations the existing framework was not designed for.

Supervisory contact. A Dear CEO letter, a data request, a thematic review or an FCA visit tends to expose whether documentation reflects practice.

Key person departure. The loss of a compliance officer or MLRO leaves an accountability gap that must be filled quickly.

Transaction activity. Change in control, acquisitions and investment rounds require regulatory due diligence and FCA notification.

Audit or assurance requirements. Safeguarding audits, client money audits and internal audit findings frequently generate remediation programmes.

Engagement models and cost

Three structures dominate the market.

ModelTypical useHow it is priced
Fixed-fee projectAuthorisation applications, VoPs, change in control, policy suite buildSingle fee against a defined deliverable and defined assumptions
Retained supportOngoing compliance resource, monitoring, board reportingMonthly fee against an agreed hour allocation or service schedule
Day rate or reviewCompliance audits, financial crime reviews, s166 readiness, remediationDay rate, or fixed fee for a scoped review with a written report

Price alone is a poor signal. What matters is the scope definition: what is included, what is expressly excluded, who performs the work, what happens when the FCA raises follow-up questions, and whether case officer correspondence sits inside or outside the fee. A low headline fee with narrow scope frequently costs more once the application enters detailed assessment.

What the FCA expects when compliance is outsourced

Using an external provider does not transfer accountability. Under SYSC, a firm remains fully responsible for discharging all of its obligations, and outsourcing must not impair the quality of internal control or the FCA's ability to supervise the firm.

Practically, that means:

  • A written agreement setting out the services, standards and responsibilities.
  • A named senior manager inside the firm who owns the relationship and the underlying obligation. Under SM&CR the relevant prescribed responsibility cannot be delegated to a third party.
  • Oversight of the provider's performance, evidenced rather than assumed.
  • Access and audit rights, and appropriate data protection and confidentiality terms.
  • An exit plan, so that the firm can bring the activity back in-house or move provider without disruption.

Our guides to outsourcing obligations for payment institutions and EMIs and third party outsourcing due diligence under SYSC 8 set out the requirements in detail.

How to choose

Sector-specific authorisation experience. Ask how many applications the team has taken through determination in your specific permission set within the last twenty-four months, and what the outcomes were. Payment services, e-money, cryptoassets, consumer credit and MiFID investment business each carry different evidential expectations.

Who does the work. Establish whether the individual in the pitch is the individual who will draft the business plan and speak to the case officer, or whether delivery passes to a junior team.

Regulator engagement track record. Direct experience of case officer correspondence, information requests and supervisory meetings is materially different from policy drafting.

Depth of the policy output. Generic template suites are visible to case officers and are a common cause of challenge. Documentation must reflect the firm's actual operating model, systems and risk profile.

Independence. Where the engagement is an audit or independent review, the provider should not be reviewing its own prior work without disclosure.

Continuity. Authorisation projects run for months and supervisory relationships run for years. Team stability matters.

Professional indemnity cover and contractual terms. Confirm cover levels, liability caps, and the position on work product ownership.

Questions worth asking before you sign

  • What exactly is in scope, and what is expressly out of scope?
  • What are your assumptions on the number of FCA question rounds included?
  • Who is the named lead, and what proportion of the work will they personally perform?
  • What does the deliverable look like? Ask for a redacted example.
  • How do you handle a change of regulatory position mid-project?
  • What are the notice terms, and what happens to work product on exit?
  • How will you evidence the work so that it stands up to supervisory review?

Where value is created and lost

Value is created where external support brings pattern recognition: knowing how a case officer will read a business plan, which control gaps consistently attract challenge, what a proportionate framework looks like for a firm of a given size, and how to close a finding in a way that does not create a new one.

Value is lost where documentation is produced without reference to how the firm actually operates. A policy suite that describes controls the firm does not perform is worse than no policy suite, because it evidences a governance failure rather than a documentation gap.

About Regulatory Counsel

Regulatory Counsel advises UK and international financial services firms on authorisation, prudential and conduct requirements, governance, financial crime and regulator engagement.

Our compliance support work covers FCA authorisation and variation of permission applications, retained compliance support, compliance monitoring programmes, policy framework design, financial crime and safeguarding reviews, Consumer Duty implementation, regulator correspondence and remediation programmes.

Contact our regulatory team at info@regulatorycounsel.co.uk.

This article is provided for general information and does not constitute legal or regulatory advice. Firms should confirm the current position against FCA publications and take advice on their specific circumstances.

Frequently Asked Questions

Typical work covers authorisation and permissions applications, ongoing compliance support such as monitoring and board reporting, independent reviews and audits, and remediation or regulator engagement following supervisory contact.

Engagements are usually priced as a fixed fee for a defined project such as an authorisation application, a monthly retainer against an agreed hour allocation, or a day rate for review work. Scope definition matters more than headline price.

A firm can outsource compliance activity but not accountability. Under SYSC the firm remains fully responsible, the arrangement must not impair internal control or FCA supervision, and a named senior manager must retain ownership of the obligation.

No. Prescribed responsibilities sit with approved senior managers within the firm and cannot be transferred to an external provider. The senior manager must be able to demonstrate reasonable steps, including oversight of the provider.

Common triggers include an authorisation or variation of permission application, growth into new products or jurisdictions, supervisory contact such as a Dear CEO letter or information request, departure of a compliance officer or MLRO, and transaction activity requiring change in control notification.

Sector-specific authorisation experience with recent outcomes, who personally performs the work, direct regulator engagement experience, the depth and bespoke quality of deliverables, independence where the work is an audit, and contractual terms including liability and exit.

Need Expert Advice?

Free initial consultation. No obligation.

Speak to an Expert